39
1
(ii) in a manner that protects from
2
unauthorized use or disclosure any cyber
3
threat indicators that may contain personal
4
information or information that identifies
5
specific persons; and
6
(iii) in a manner that protects the
7
confidentiality of cyber threat indicators
8
containing personal information or infor-
9
mation that identifies a specific person.
10
(D) FEDERAL
11
(i) IN
REGULATORY AUTHORITY.—
GENERAL.—Except
as provided
12
in clause (ii), cyber threat indicators and
13
defensive measures provided to the Federal
14
Government under this title shall not be
15
directly used by any Federal, State, tribal,
16
or local government to regulate, including
17
an enforcement action, the lawful activities
18
of any entity, including activities relating
19
to monitoring, operating defensive meas-
20
ures, or sharing cyber threat indicators.
21
(ii) EXCEPTIONS.—
22
(I)
REGULATORY
AUTHORITY
23
SPECIFICALLY RELATING TO PREVEN-
24
TION OR MITIGATION OF CYBERSECU-
25
RITY THREATS.—Cyber
† S 754 ES
threat indica-